Showing posts with label cyber-security. Show all posts
Showing posts with label cyber-security. Show all posts

13 August 2012

Means and Ends

Ross Clark’s article, Our China Syndrome, in the current Spectator (summary here) was sub-headed The claims against swimmer Ye Shiwen reflect irrational suspicion of her country, a theme which he expanded on:
Rarely can a sporting performance have been met with such resentment as that of 16-year-old Ye Shiwen in the 400 metres women’s medley. She had hardly wiped the drops from her goggles before the US swimming coach John Leonard was making coded accusations of drug use, with words such as ‘unbelievable’ and ‘disturbing’. Her offence, it seems, was to have swum a length of the pool faster than an all-American winner of the men’s event, Ryan Lochte.  
… Ye Shiwen had passed the routine drugs test to which all medal winners at the Olympics have been subjected. She wasn’t a drugs cheat after all, …  
Deprived of the opportunity to accuse her of doping, the nation’s Sinophobes changed tack. Maybe she wasn’t on drugs, but she was the product of a ‘brutal training regime’ … Then came the extraordinary accusation that she might have been genetically modified. …  
BBC’s Newsnight devoted its main story to the fantasy that athletes might be having their genes modified to improve their performance — interspersed with clips of Ye Shiwen winning her medals. After 15 minutes of this, the scientists invited on the programme to discuss the issue admitted that there was no evidence it was actually possible to manipulate an athlete’s genes in this way.
There is certainly no question of Ye Shiwen having failed any tests. However, the scientific position may not be as categorical as Clark was assuming. The Times monthly science supplement, Eureka, gave its August issue over to Science and the [Olympic] Games, including an article by Kaya Burgess, Testing times: getting ahead of the cheats, in which she tries to answer the question:
The doping authorities at London 2012 are implementing the most stringent drug testing regime of any Games. But can cheats still slip through?  
… There is little doubt that there are more ways to cheat in sport than ever. Since the British Olympic Association first started working on the Olympic bid, in 1997, performance enhancement has evolved beyond the abuse of steroids and stimulants to include ever-subtler ways of enhancing the body from within. The challenge for UK Anti-Doping (UKAD) is to try, at last, to get one step ahead. This year, every medallist will be tested, and so will about half of all other athletes competing. More than 6,000 samples are expected to be analysed in the course of the Games. But the testers at the Olympic testing laboratory in Harlow have to know what they are looking for.  
… Existing drugs approved for medical use will already be on the radar of the World Anti-Doping Agency (Wada), which will have analysed the potential for cheats and prepared watertight arguments against those who claim innocent use. What Wada has not known about until now, however, is the vast range of drugs still in secret development by pharmaceutical companies. For the first time, one of those companies, GlaxoSmithKline, has opened its drug-research pipeline to Wada to help officials flag up new or unknown substances that may have found their way into athletes’ hands through other sources. …  
Steve Clarke, GSK’s head of drug metabolism and pharmacokinetics, … cites the example of Balco — the Bay Area Laboratory Co-Operative, near San Francisco — which was found to have sold steroids, growth hormones, testosterone cream and erythropoietin to Major League baseball players as well as Chambers. “They had looked through the literature, come up with a steroid drug that wasn’t marketed anywhere but that had been investigated as a potential at one stage, and they had chemists capable of making that drug,” Clarke says. The result was a drug that Wada didn’t know about and didn’t have a test for. “That’s why athletes got away with it for so long and why THG was known as ‘The Clear’.”
As Burgess concludes, it wouldn’t be sensible to bet against competitors breaking the rules, perhaps under pressure. None of this reflects in any way upon Ye Shiwen, but she does come from a country which plays with a hard ball and where ends seem to justify means. I have posted here before about Chinese hacking and cyber theft, but some more insight into what has been happening was provided by Bloomberg just as the Olympics opened in an article by Michael Riley and Dune Lawrence, Hackers Linked to China’s Army Seen From EU to D.C., which anyone with the slightest interest in the subject should read in full. Apart from the EU and various organisations in Washington DC, the article reports attacks on computers in Canada and India, and:
The networks of major oil companies have been harvested for seismic maps charting oil reserves; patent law firms for their clients’ trade secrets; and investment banks for market analysis that might impact the global ventures of state-owned companies, according to computer security experts who asked not to be named and declined to give more details.  
… Stolen information is flowing out of the networks of law firms, investment banks, oil companies, drug makers, and high technology manufacturers in such significant quantities that intelligence officials now say it could cause long-term harm to U.S. and European economies.
The article revealed that:
Adding a potentially important piece to the puzzle, researcher Joe Stewart, who works for Dell SecureWorks, an Atlanta-based security firm and division of Dell Inc. (DELL), the computer technology company, last year uncovered a flaw in software used by Comment group hackers. Designed to disguise the pilfered data’s ultimate destination, the mistake instead revealed that in hundreds of instances, data was sent to Internet Protocol (IP) addresses in Shanghai. The location matched intelligence contained in the 2008 State Department cable published by WikiLeaks that placed the group in Shanghai and linked it to China’s military.
Perhaps China’s pharma technology base is nothing like as advanced as their cyber capability, but if it is they could probably run Olympic-sized rings around UKAD and Wada, if they set out to do so. The scope in the long term for innovations of all sorts, overt and covert, in a country in which even a fraction of its population reaches the PISA standards recorded for Shanghai’s 15-year olds in 2009 will be immense.

12 March 2012

The Times and the cyber techies (a techie gets tetchy)

From the online Oxford English Dictionary:
techie, n.
3.colloq. (chiefly U.S.). An expert in or enthusiast for technology, esp. computing; (also) a technician. Cf. techy adj.
techy, adj.1
Forms: 19– techie, 19– techy
Technologically sophisticated or complicated; characterized by expertise in or enthusiasm for technology, esp. computing. Cf. techie n. 3.

Pauline Neville-Jones’ opinion piece in The Times (£) on 9 March about cyber-security, Wanted: workers to fill half a million jobs, was subtitled In retail, defence, business and the police the hunt is on for ‘techies’. Could you be one? I will come to the rest of her article later, but the use of the term 'techie' intrigued me. I apply it to myself in this blog’s Profile, but I didn’t recall seeing it in The Times very often, if at all. So I searched the Times online database to derive the statistics for its use since 1 Jan 2011:


Bear in mind that over this period there will have been about 60 issues of the Sunday Times and about 360 of The Times, so you would have come across “techie/techies”, in one sense or the other, twice in 28 issues of The Times or in 6 issues of the Sunday Times. As an adjective, it’s often used to describe people: techie types, techie blokes, or even techie nerds. In fact, there is almost always a hint of deprecation about it (yes, by me too!).

The purpose of Neville-Jones’ article was to emphasise the importance of cyber-security and the consequent need for people with the skills needed to combat theft and espionage carried out against IT-based systems. Reading it, the prospects don’t look too good:
Government figures show that we will need more than half a million new IT professionals over the next five years. … The number of British students applying for IT-related courses is going down year on year, while foreign nationals fill the places. …
How can it be that in a field so central to this nation’s future and so potentially rewarding to those in it, we should be staring at a skills gap of daunting proportions and significance? …
The skills gap, which has its roots in the catastrophic decline in the teaching of STEM subjects (science, technology, engineering, maths) over the past decade, is at last being gripped. The current inadequate ICT curriculum is being radically upgraded and new courses being developed. But will these courses be taught? Today, half the teacher training places in maths are unfilled and far too few British students are filling the centres of excellence in computer science at our universities.
In posts over the last 18 months I have touched on some of the underlying issues. For example: the way the terms engineer and technician are abused in the UK; how different things are in China; the realities of STEM training – the “math-science death march”.   Neville-Jones almost gave the game away when she remarked:
IT jobs are widely seen as being “techie” and dull. Not all of this is wide of the mark.
but then recovered with:
There is a real job to be done by existing professional bodies, universities and the Government to tell people just how broad, varied and rewarding a profession this is.
The Rt Hon. The Baroness Neville-Jones, DCMG (as Wikipedia indicates she should be styled) is a former diplomat who occupied important intelligence and national security posts, became a Conservative politician and then Minister of State for Security and Counter-Terrorism at the Home Office, and is now (as The Times article stated) “Special Representative to Business on Cyber Security”. Her own degree (Modern History from Oxford) was far from techie, and although she has no children of her own, I would be surprised if any of her godchildren, nieces, nephews and so on have pursued STEM-based occupations. To understand why that is likely to be the case when talking about the offspring of the UK’s elite, it’s helpful to return to the examples from Times online because these reveal their underlying attitudes towards “techie” types:
Who says techie types can’t connect? The Times 7 Feb 12
often the techies are not so hot on writing Sunday Times 20 Nov 11
a proper techie with thick-rimmed glasses The Times 30 Apr 11
Even the techies got excited The Times 19 Mar 11
sounding as emotional as a techie can get The Times 19 Mar 11
which shows that, in techie terms, I’m relatively up to speed The Times 16 Mar 11
(The Secretary of State for Education’s wife, that one)
we had an interval while the techies fiddled around with the communications systems Sunday Times 13 Mar 11
the sort of scientific language beloved of techies The Times 12 Mar 11
some slightly less chic techie types on the mezzanine The Times 19 Feb 11
Not greatly encouraging. But as I pointed out a year ago:
… “high achievers from poor families” don’t just lack material resources, but also … face a shortfall in “social capital” including access to networks, contacts and internships. In these circumstances, taking STEM subjects (science, technology, engineering, maths), where what you know matters rather more than who you know, may be a better strategy than taking softer options with a more uncertain access to employment.
Meanwhile in China, a chemical engineering graduate from Beijing's prestigious Tsinghua University, Xi Jinping, is about to become President. While Baroness Neville-Jones probably doesn’t read the New Scientist very often, or even The Times’ monthly Eureka supplement, she is almost certain to be familiar with the prestigious US journal Foreign Affairs. She might then have found Adam Segal’s Feature article, Chinese Computer Games in March/April 2012’s issue, interesting, if a little depressing:
In February 2011, weeks after Google publicly announced that hackers had tried to steal its sensitive computer codes, security experts traced the attacks back to Shanghai Jiao Tong University and a vocational school in Shandong Province. Both schools denied any involvement, and it is possible that their computers were hijacked by others, but U.S. intelligence officials claim that 20 groups associated with the People’s Liberation Army and several Chinese universities are responsible for the majority of the attacks on Google, RSA, and other U.S. targets. Attributing responsibility is often hard. Some hackers drift in and out of Beijing’s orbit over time, whereas others are independent criminals with no links to the state. Overall, however, much of the hacking originating in China can be classified as government-sponsored or government-tolerated. Beijing sees such hacking as a good way to eke out economic and military advantage …
Segal would like to see a consensus built up between the US and Chinese governments, both sides recognising their common interests in an interoperable and high integrity internet. This is more a job for diplomats than techies:
Diplomats should take their cues from the planned dialogue on cyberspace between the United States and Russia, which is to include discussions about how each side’s military views the Internet and an effort to establish a hot line that could be used during a cybersecurity crisis. Washington and Beijing need to have a clear communications channel in case of emergency. To build trust over the longer term, the two sides should also discuss some common threats, such as the potential for terrorist attacks on power grids.
Nonetheless, he concludes:
Assembling an international consensus on norms about cyberspace, however, is a strategy that will probably take a long time to pay off, if it ever does. There is little the United States can do to alter China’s conception of cyberspace, a vision it is actively promoting abroad. With a growing population of 500 million Internet users, it is easy to see why the Chinese believe that the future of cyberspace belongs to them. In the meantime, the most pressing tasks for the United States are to raise the costs incurred by Chinese hackers and to improve the security of networks at home. Yet U.S. officials should be realistic: Chinese-based cyberattacks will not disappear anytime soon.
which all suggests that if you embark on a career as a cyber-security techie, it should last for years.

ADDENDUM 13 March

Anyone who has read all above will probably find this article interesting, particularly the different national perspectives, as were identified by Segal.